CISSP PRACTICE QUESTIONS – 20200624

Effective CISSP Questions

You are the CISO at Wonderland county government. The incident response team reports to you that unknown ransomware has successfully attacked the county’s file servers and encrypted production data. As a CISO, which of the following do you think the IR team should conduct next?
A. Identify the root cause and remediate the problem
B. Prioritize the incident
C. Isolate infected machines
D. Validate if the incident is true

Wentz’s Book, The Effective CISSP: Security and Risk Management https://www.amazon.com/dp/B087JL6BXR

Continue reading →

CISSP PRACTICE QUESTIONS – 20200623

Effective CISSP Questions

Your company is awarded a contract to develop a customized firewall product for a well-known brand security company. As a security professional, you are a member of the integrated product team. After a workshop for collection and elicitation of protection needs from the customer and stakeholders, you finished specifying security functional and assurance requirements. Which of the following activities conducted by the quality assurance team ensures the product compliant with the specifications? 
A. Certification
B. Accreditation
C. Verification
D. Validation

Wentz’s Book, The Effective CISSP: Security and Risk Management https://www.amazon.com/dp/B087JL6BXR

Continue reading →

MAC Security Issues

  • Inference: Derivation of new information from known information. The inference problem refers to the fact that the derived information may be classified at a level for which the user is not cleared. The inference problem is that of users deducing unauthorized information from the legitimate information they acquire.
  • Aggregation: The result of assembling or combining distinct units of data when handling sensitive information. Aggregation of data at one sensitivity level may result in the total data being designated at a higher sensitivity level.
  • Polyinstantiation: Polyinstantiation allows a relation to contain multiple rows with the same primary key; the multiple instances are distinguished by their security levels.
  • Referential integrity: A database has referential integrity if all foreign keys reference existing primary keys.
  • Entity integrity: A tuple in a relation cannot have a null value for any of the primary key attributes.
  • Granularity: The degree to which access to objects can be restricted. Granularity can be applied to both the actions allowable on objects, as well as to the users allowed to perform those actions on the object.

Source: NIST SP 800-8 (obsoleted)

References

CISSP PRACTICE QUESTIONS – 20200622

Effective CISSP Questions

Your company develops security products. You are the head of the firewall product line and decide to develop a new firewall model. Formal methods will be used for specification, verification, and other aspects of product development. Which of the following is not a formal method?
A. Fagan inspection
B. Delphi method
C. Lattice-based access control
D. Finite-state machine

Wentz’s Book, The Effective CISSP: Security and Risk Management https://www.amazon.com/dp/B087JL6BXR

Continue reading →

CISSP PRACTICE QUESTIONS – 20200621

Effective CISSP Questions

Your company develops security products. You are the head of the firewall product line and decide to develop a new firewall model based on formal designs. Which of the following best supports the design for the product?
A. Use a prescribed system development life cycle (SDLC) compliant with standards
B. Follow the design principle of encapsulation and modulization and best practices
C. Employ a state machine and ensure secure transit between states
D. Gain certification from third-party evaluation for assurance

Wentz’s Book, The Effective CISSP: Security and Risk Management https://www.amazon.com/dp/B087JL6BXR

Continue reading →

CISSP PRACTICE QUESTIONS – 20200620

Effective CISSP Questions

Your company is implementing the ERP system. As a security professional, you are selecting security controls as a baseline from a well-known security control framework and customizing it according to your company’s specific requirements and constraints. Which of the following is the least concern during the process of scoping and tailoring?
A. Compensating controls
B. Common controls
C. The impact level of the ERP system
D. Certification and accreditation

Wentz’s Book, The Effective CISSP: Security and Risk Management https://www.amazon.com/dp/B087JL6BXR

Continue reading →

Wentz’s PICS

To Inspire People

I am happy to announce Wentz’s PICS for CISSP is now available to my readers for free.

Wentz’s PICS

Wentz’s Powerful Inquiry Coaching Session (PICS) is a coaching service conducted in the form of a small group. It features a highly interactive to-the-point process of questioning and answering. It used to be a one-on-one service that is now extended to a small group and applied in the area of CISSP preparation.

Wentz’s PICS for CISSP

Wentz’s PICS is free for readers of Wentz’s book, The Effective CISSP: Security and Risk Management. It is Wentz’s initiative of a one-hour session to help readers to think about some essential issues and read the book more effectively and efficiently.

Please visit Wentz’s PICS CISSP for details.

 

CISSP PRACTICE QUESTIONS – 20200619

Effective CISSP Questions

You are implementing a company network for a startup. The IP address of the intranet is 192.168.1.0/24. You split the intranet into two subnets connected by a router: 192.168.1.0/25 and 192.168.128.0/25. Which of the following is the best for the router to forward IP packets from one subnet to the other?
A. Relay agent
B. Routing protocols
C. Routed protocols
D. Static routes

Continue reading →

A flock of eagles landed!

20200626-Get Your Copy Right Now

A flock of eagles landed!

I received 50 author copies today.  Amazon KDP doesn’t disappoint me. Even though my author copies take 6 weeks to arrive in my office, the quality of the final work is exactly what I want as that I printed in Taiwan.


一群老鷹總算來了!

當初為了趕出版時間, 我選擇在台灣打樣. 而沒有跟美國Amazon KDP確認最終樣本就直接上架了(Amazon還要印樣書, 由美國寄到台灣作確認實在太久了). 還好Amazon沒讓我失望, 他們的印刷品質跟我在台灣印刷幾乎相同, 實在很棒!

今天總算收到從Amazon寄出的作者專書, 前後雖然花了6週才由美國送到我的辦公室, 但看到最終的品質, 也算是彌補了一點缺憾!

每本書都像一隻老鷹, 以銳利的眼光在高空緃觀全局以尋找獵物(CISSP)! 希望這本書能像老鷹一樣, 協助正在準備CISSP考試的朋友順利擒獲CISSP這隻獵物!

購買連結

  1. Amazon購買連接: https://www.amazon.com/dp/B087JL6BXR
  2. 直接向Wentz購買這本書: https://wentzwu.com/buy